Forum Discussion

nplfish's avatar
nplfish
Copper Contributor
Sep 07, 2022

KQL queries for investigative purposes in Microsoft 365 Defender

Quite new to KQL but wanted to how one could use it to enhance or help an investigation of an Alert/Incident I know this may sound generic but any suggestions ,ideas or examples will be appreciated 

Resources